CVE-2025-1128
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 25, 2025
Updated: Feb 28, 2025
CWE ID 434
Summary
CVE-2025-1128 is a vulnerability affecting the Everest Forms plugin for WordPress. This issue, present in all versions up to 3.0.9.4, enables unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server. The 'format' method in the EVF_Form_Fields_Upload class lacks proper file type and path validation, making it exploitable. The potential consequences include remote code execution, sensitive information disclosure, or a complete site takeover.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share